| File name: | MouseServer.exe |
| Full analysis: | https://app.any.run/tasks/230fdfa3-62ca-4df6-95c3-3c697d70e3e4 |
| Verdict: | Malicious activity |
| Analysis date: | March 06, 2024, 07:52:38 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F55F4358135B428BA954ADBB55D32A57 |
| SHA1: | B2BCEF855CDEE818941974CFD52737B73C24DBA6 |
| SHA256: | 6CE361B0A7BF6FD1DCE9E3D71674DA3D3A64C401ED94722E6EA4D3F98F4EA7C0 |
| SSDEEP: | 98304:h3F5+HCnCPrhxdHLUdT3UMSIm4yT1Jj38YtCxTuQbmQoxfJS+2KAv79ckiUjK/Vg:tPB |
| .exe | | | Inno Setup installer (81.5) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10.5) |
| .exe | | | Win32 Executable (generic) (3.3) |
| .exe | | | Win16/32 Executable Delphi generic (1.5) |
| .exe | | | Generic Win/DOS Executable (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 41472 |
| InitializedDataSize: | 71168 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xaa98 |
| OSVersion: | 1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.8.2.5 |
| ProductVersionNumber: | 1.8.2.5 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | 深圳市油桃科技有限公司 |
| FileDescription: | MouseServer.exe Setup |
| FileVersion: | 1.8.2.5 |
| LegalCopyright: | Copyright © 2021-2022 深圳市油桃科技有限公司 |
| ProductName: | MouseServer.exe |
| ProductVersion: | 1.8.2.5 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 568 | "Mouse Server Luminati.exe" | C:\Program Files\MouseServer.exe\Mouse Server Luminati.exe | MouseServer.exe | ||||||||||||
User: admin Company: 深圳市油桃科技有限公司 Integrity Level: HIGH Description: Mouse Server Luminati.exe Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 992 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1452 --field-trial-handle=1384,i,8635822150141927425,5471018072636467801,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1040 | "C:\Program Files\MouseServer.exe\net_updater32.exe" --install-ui win_wifimouse.necta.us --dlg-app-name "Mouse Server" --dlg-tos-link "http://wifimouse.necta.us/MouseServerPrivacy.htm" --dlg-logo-link "http://wifimouse.necta.us/mouseserver.png" --dlg-bg-color "#ffffffff" --dlg-btn-color "#ff323232" --dlg-txt-color "#ff000000" --dlg-not-peer-txt limited --dlg-pos screen --dlg-benefit-txt "WiFi Mouse landscape keyboard & game pad | C:\Program Files\MouseServer.exe\net_updater32.exe | — | MouseServer.tmp | |||||||||||
User: admin Company: Bright Data Ltd. Integrity Level: HIGH Description: BrightData service allows free use of certain features in an app you installed Exit code: 2 Version: 1.305.614 Modules
| |||||||||||||||
| 1556 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1220 --field-trial-handle=1336,i,12531485395011300818,7326397744170345363,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1776 | "C:\Users\admin\AppData\Local\Temp\MouseServer.exe" | C:\Users\admin\AppData\Local\Temp\MouseServer.exe | explorer.exe | ||||||||||||
User: admin Company: 深圳市油桃科技有限公司 Integrity Level: HIGH Description: MouseServer.exe Setup Exit code: 0 Version: 1.8.2.5 Modules
| |||||||||||||||
| 1888 | "C:\Program Files\MouseServer.exe\MouseServer.exe" | C:\Program Files\MouseServer.exe\MouseServer.exe | MouseServer.tmp | ||||||||||||
User: admin Company: 深圳市油桃科技有限公司 Integrity Level: HIGH Description: MouseServer.exe Exit code: 0 Version: 1.8.2.5 Modules
| |||||||||||||||
| 2068 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2148 --field-trial-handle=1384,i,8635822150141927425,5471018072636467801,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2112 | C:\Program Files\MouseServer.exe\test_wpf.exe | C:\Program Files\MouseServer.exe\test_wpf.exe | — | Mouse Server Luminati.exe | |||||||||||
User: admin Company: Bright Data Ltd. Integrity Level: HIGH Description: test_wpf Exit code: 0 Version: 1.305.614 Modules
| |||||||||||||||
| 2156 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://wifimouse.necta.us/install/success.html | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | MouseServer.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2404 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1608 --field-trial-handle=1384,i,8635822150141927425,5471018072636467801,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (2964) MouseServer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 940B0000C053134C9B6FDA01 | |||
| (PID) Process: | (2964) MouseServer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: B71A3ED5DBA69BB7B21494B00667F70EBE5361791F9ED47016BB6C91171E7554 | |||
| (PID) Process: | (2964) MouseServer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2964) MouseServer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\MouseServer.exe\MouseServer.exe | |||
| (PID) Process: | (2964) MouseServer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: 375A41FE44135ADD8CFEC54A06A399DBB0FDF92C3A56926EFDC35ED97066D185 | |||
| (PID) Process: | (2964) MouseServer.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7AFAA880-BB05-4E38-9279-C53EECE1B7BE}_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 5.5.9 (a) | |||
| (PID) Process: | (2964) MouseServer.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7AFAA880-BB05-4E38-9279-C53EECE1B7BE}_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\MouseServer.exe | |||
| (PID) Process: | (2964) MouseServer.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7AFAA880-BB05-4E38-9279-C53EECE1B7BE}_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\MouseServer.exe\ | |||
| (PID) Process: | (2964) MouseServer.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7AFAA880-BB05-4E38-9279-C53EECE1B7BE}_is1 |
| Operation: | write | Name: | Inno Setup: Icon Group |
Value: (Default) | |||
| (PID) Process: | (2964) MouseServer.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7AFAA880-BB05-4E38-9279-C53EECE1B7BE}_is1 |
| Operation: | write | Name: | Inno Setup: User |
Value: admin | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2964 | MouseServer.tmp | C:\Program Files\MouseServer.exe\is-M4J3L.tmp | executable | |
MD5:52C7C8CF5D10D306D0411B05C9E05C4C | SHA256:84402A052CD97B4A00DB2A4D90DCF2F6290E66C1A3938491795873A217B8CF9B | |||
| 2964 | MouseServer.tmp | C:\Program Files\MouseServer.exe\MouseServer.exe | executable | |
MD5:15BC951073B34180E791959BFD23935E | SHA256:F7A3284ACD6A6B0B901946BFE1476AA5F654D4ADA0F568D19939EF79EE376443 | |||
| 2964 | MouseServer.tmp | C:\Program Files\MouseServer.exe\is-94F39.tmp | executable | |
MD5:2EBFED79BBF5704145293351BDDC424B | SHA256:2DFACDF691719ABC60494C96D1216E47E91919D6A2A3538343249534878B3DE7 | |||
| 2964 | MouseServer.tmp | C:\Program Files\MouseServer.exe\BluetoothAdapter.dll | executable | |
MD5:2EBFED79BBF5704145293351BDDC424B | SHA256:2DFACDF691719ABC60494C96D1216E47E91919D6A2A3538343249534878B3DE7 | |||
| 2964 | MouseServer.tmp | C:\Program Files\MouseServer.exe\is-VN427.tmp | executable | |
MD5:15BC951073B34180E791959BFD23935E | SHA256:F7A3284ACD6A6B0B901946BFE1476AA5F654D4ADA0F568D19939EF79EE376443 | |||
| 2964 | MouseServer.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MouseServer.exe.lnk | lnk | |
MD5:83E71424441F21E3D652EE2EA1B1FDAA | SHA256:E60026F232CD7FF96E4A810007E984722C33929E903592F5703055A2F3EC74BF | |||
| 2964 | MouseServer.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\(Default)\MouseServer.exe.lnk | binary | |
MD5:D3729175C689CDF74493EBE025C591CF | SHA256:6C93FD4DE4AA73A38098680495E8974048231A663FCD7BA66FF93C0E94B650FD | |||
| 2964 | MouseServer.tmp | C:\Program Files\MouseServer.exe\is-3DG3L.tmp | executable | |
MD5:A71CD0D7859F5D2402717D987A54C798 | SHA256:8A25F2444C4D1B9F9BB96EFEC392A78412FFF5BA44D7B864E263509B7194064D | |||
| 2964 | MouseServer.tmp | C:\Program Files\MouseServer.exe\unins000.dat | dat | |
MD5:DF91B6DFCFF7F243A21F6885CCCEF0DE | SHA256:2706D65572F74609C5E0E5CFE0B8B17215C8A470DF25BF283F176FA673F6DA59 | |||
| 2964 | MouseServer.tmp | C:\Users\Public\Desktop\MouseServer.exe.lnk | lnk | |
MD5:109487682EE4F25A6B8AF7BA93BAB4F6 | SHA256:EF9A61C4A554A033B01886B4CE9D3BB579CD3D3BD57C99E5AAECE7FFED8198E0 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3428 | net_updater32.exe | GET | 301 | 162.144.62.9:80 | http://wifimouse.necta.us/mouseserver.png | unknown | html | 250 b | unknown |
992 | msedge.exe | GET | 301 | 162.144.62.9:80 | http://wifimouse.necta.us/install/success.html | unknown | html | 255 b | unknown |
3428 | net_updater32.exe | GET | 200 | 23.223.209.21:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?6578879dcf199db3 | unknown | compressed | 67.5 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
3428 | net_updater32.exe | 192.81.214.145:443 | perr.lum-sdk.io | DIGITALOCEAN-ASN | US | unknown |
3428 | net_updater32.exe | 3.228.36.186:443 | clientsdk.lum-sdk.io | AMAZON-AES | US | unknown |
3428 | net_updater32.exe | 162.144.62.9:80 | wifimouse.necta.us | UNIFIEDLAYER-AS-1 | US | unknown |
3428 | net_updater32.exe | 162.144.62.9:443 | wifimouse.necta.us | UNIFIEDLAYER-AS-1 | US | unknown |
3428 | net_updater32.exe | 23.223.209.21:80 | ctldl.windowsupdate.com | Akamai International B.V. | US | unknown |
1888 | MouseServer.exe | 192.168.100.255:2008 | — | — | — | whitelisted |
3680 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
perr.lum-sdk.io |
| unknown |
perr.l-err.biz |
| unknown |
clientsdk.lum-sdk.io |
| unknown |
wifimouse.necta.us |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
cdnjs.cloudflare.com |
| whitelisted |
fonts.googleapis.com |
| whitelisted |
ajax.googleapis.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .biz TLD |